PT-2022-21953 · Unknown · Dproxy-Nexgen

Haya Shulman

+2

·

Published

2022-08-15

·

Updated

2022-08-18

·

CVE-2022-33991

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions dproxy-nexgen (affected versions not specified)
Description The issue concerns dproxy-nexgen forwarding and caching DNS queries with the CD bit set to 1, which leads to the disabling of DNSSEC protection provided by upstream resolvers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2022-33991

Affected Products

Dproxy-Nexgen